I want to expose my services publicly on my own domain name, how would you guys do that?

I have seen people using Cloudflare, but I don’t want to use Cloudflare out of principle. I have also seen stuff on caddy and frp that I’ve done some rough researching.

What do you guys do?

  • spork@pawb.social
    link
    fedilink
    English
    arrow-up
    33
    ·
    edit-2
    28 days ago

    I rent a cheap VPS with iptables routing ports through a wireguard tunnel to a peer on the local network that acts as a firewall and reverse proxy, this gives you a static IP with a local control plane and no ddns.

    • HelloRoot@lemy.lol
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      edit-2
      28 days ago

      Same but nftables and also crowdsec.

      Also I had some trouble with the wireguard tunnel dropping lots of packets, which resulted in my services not loading 50% of the time. I did a lot of suggestions at the same time so I’m not sure which one fixed it but here is a list in case anybody has similar troubles:

      • lowering MTU
      • routing ipv6 through the tunnel as well
      • rewriting nftables rule order

      (will update after work, notes are at home)

            • /home/pineapplelover@lemmy.dbzer0.comOP
              link
              fedilink
              English
              arrow-up
              1
              ·
              27 days ago

              Is there a data cap? I’m concerned like they only allow me to pass through like a TB or so of data passing through it within a month. If you have users watching your jellyfin server every day that can surpass your limit.

              • Jason2357@lemmy.ca
                link
                fedilink
                English
                arrow-up
                0
                ·
                27 days ago

                Keep in mind that you wouldn’t route local traffic through it, so everything watched at home would be direct and not count.

                I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.

                A VPS takes some learning, but IMHO, it is the “correct” answer and worthile learning.

    • halcyoncmdr@piefed.social
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      28 days ago

      Similar here. Just a Digital Ocean droplet running Pangolin. Functions basically the same as the cloudflare tunnel it replaced.

      Can expose the service directly if needed, or from behind a login page.

  • fozid@lem.radiantfig.fyi
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    1
    ·
    edit-2
    28 days ago

    A reverse proxy is the traditional safe route. Use a web server like Apache, nginx or caddy, and setup to reverse proxy all your services through port 443, and use let’s encrypt and certbot to generate and manage TLS certificates.

    I host around 15 public facing web services this way using nginx.

    Just be aware, this is very public facing so server security and hardening is important. Things like strong passwords, disabled root, use ssh keys instead of passwords, setup fail2ban, setup crowdsec etc.

    The more modern safer way is not to truly expose to full public and use things like tailscale or cloudflare tunnels. But this relies on 3rd party servers and I’m not a fan of that, but it does bring benefits.

  • myrmidex@belgae.social
    link
    fedilink
    English
    arrow-up
    8
    ·
    edit-2
    28 days ago

    I got off CloudFlare by using Pangolin. Ideal for my use-case, I didn’t use any of CF’s advanced features, so Pangolin is the ideal replacement for me.

    Publicly serves everything from static sites to forgejo (+the ssh endpoint for git pushes).

  • ISolox@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    2
    ·
    28 days ago

    Reverse proxy is what you need. I would post instructions here but honestly they wouldnt be that good. Just search it up and follow along.

  • Nibodhika@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    28 days ago

    Why do you want to expose them? This might limit the solutions.

    The way I do this is in 2 different ways:

    1. Tailscale, my server connects to tailscale so all I have to do is connect to it from my phone and I can access things remotely easily. This is the best for most things, but has the downside that others can’t access it as easily

    2. I have a VPS (two actually at the moment as I’m switching providers from Vultr to IONOS) that also connects to tailscale so it can access my home server through it, then using Caddy I expose the services on a subdomain of the VPS. This is what I do for things that others might want to access, or things I don’t want to have to connect to tailscale to access.

    If you’re going down the second route do consider that you will need to:

    • Add something like fail2ban or crowdsec to the VPS as attacks will happen.
    • Same reason you should add a dedicated authentication on front of most things. While I don’t expect the auth on services to be weak, it might be more vulnerable than a dedicated authentication service. You should look into Authelia, Authentik, or similar to put on front of your services so any attacker would first have to pass that to even get to your services.
  • AllYourSmurf@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    28 days ago

    Authentication & single sign-on service

    Plugged into Reverse proxy, routing to each service by name

    With a wild card cert so there are no name leaks.

    Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.

    With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.

    If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.

    • Helix 🧬@feddit.org
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      28 days ago

      If you use TLS like you should, your domains will be on the internet in the certificate transparency log. Yes, you should use a wildcard cert if you want this security by obscurity, but it’s still security by obscurity.

      • Jason2357@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        17 days ago

        Security by obscurity is when the design or archetecture of the system is obscure enough to supposedly styme attackers (it doesnt), and as soon as people understand the design, your security is broken.

        A hard to guess unpublished subdomain is a transparent and standard archetecture - nothing obscure about it and publishing that you use such a scheme doesnt break the security.

        The subdomain is a bearer token that serves as an access control and just like a key or passphrase, has a security value proportional to the bits of information an attacker has to guess.

        The real limitation is that browsers and humans are not great at not leaking domain names, so its very possible it will get leaked eventually and hard to rotate. Thats the reason they are weak. Still, they can be usefull to stop scanners just trolling for unpatched services.

  • lime!@feddit.nu
    link
    fedilink
    English
    arrow-up
    3
    ·
    28 days ago

    i configured dyndns in my router and have it forward all traffic to a gateway vm running nginx and fail2ban. every service is on a subdomain so any attempt to fetch things from the main name gets banned.

  • RanchBranch@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    3
    ·
    28 days ago

    I recently switched to Netbird on a VPS (on Vultr). Their reverse proxy is super easy to set up / self host. They also offer a free version that works pretty good too, I just wanted to make it difficult for myself (thats the whole point of self hosting, right? )

    • /home/pineapplelover@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      28 days ago

      I have seen netbird pop around every now and again. I might try out their cloud free version first and if I like it I might try self hosting it.

      So you host netbird on a vps you rent and that is used for reverse proxy? So with that reverse proxy I can have my home server be publicly accessible and I can have friends log in to my jellyfin server without having to connect to my tailnet.

      My last concern is security. How is this set up good for making sure I don’t just get constantly botted and exploited?

      • InnocentZero@kbin.earth
        link
        fedilink
        arrow-up
        3
        arrow-down
        1
        ·
        28 days ago

        Opening jellyfin up publicly is kind of asking for trouble if you ask me. I haven’t done so myself, but seen enough on this community and elsewhere to know that it’s probably not a good idea.

        • ampersandrew@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          28 days ago

          By all means correct me if you know more, but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly, only to be corrected by looking at the actual documentation. I suspect those cautioning against it are on outdated information and that Jellyfin carries much the same risk as exposing any other service.

          • irmadlad@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            28 days ago

            but what I tend to see is one or two people here saying that Jellyfin devs don’t recommend exposing it publicly

            I think what the devs are saying is ‘don’t expose Jellyfin to the public in an unsafe manner’. I don’t run Jellyfin, but can confirm what you’ve read here. In that vein, don’t expose anything to the public in an unsafe manner.

              • irmadlad@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                28 days ago

                Again, I do not run Jellyfin, but what you’re saying seems contradictory to what the devs are implying: here and here. Since I lack the hands on experience, I will leave the issue with the experts.

                • frongt@lemmy.zip
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  arrow-down
                  1
                  ·
                  28 days ago

                  That first page says exposing it to the Internet is “not recommended”. Putting a reverse proxy in front of it does not meaningfully change the security posture. A malicious request to http://jellyfin.homelab.com/exploitable-page will be sent to jellyfin in effectively the same way, whether through a reverse proxy or not. You would need a WAF set up specifically to look for relevant exploit attempts.

                  https://github.com/jellyfin/jellyfin/issues/5415

                  Those are some outstanding known vulnerabilities, most of them unfixed. They are not particularly severe, but it shows that thorough security is not a priority for the jellyfin devs.

      • InnocentZero@kbin.earth
        link
        fedilink
        arrow-up
        0
        ·
        28 days ago

        You’re probably misunderstanding what netbird does (unless I’m the one misunderstanding things?).

        Netbird subnet is equivalent to a tailscale tailnet (for all practical purposes; they even both use wireguard and hole-punching underneath). Netbird is not a reverse proxy (which I feel is what you think based on your comment).

          • RanchBranch@anarchist.nexus
            link
            fedilink
            English
            arrow-up
            1
            ·
            28 days ago

            The reverse Proxy is exactly what I use (in addition to the VPN, but I’m the only one that uses that in my group of cohorts)

            Its been in Beta for a but now, but its worked perfectly for me the entire time

  • Dirtboy@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    27 days ago

    I bought myself a Synology disk station and a domain.

    Yes I use Cloudflare for DNS so I can get a wildcard domain cert using ACME.

    I use the Synology supplied login portal as a web application firewall for every site I want to host with the wildcard SSL cert. Like bar.mydomain.com, mealie.mydomain.com, etc.

    The Synology routes the traffic to the services hosted on other services within my network.

    Anything else I don’t want open to the public web, I use the Synology supplied OpenVPN server to connect.

  • ArborNode@lemmy.shutes.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    28 days ago

    For those of us behind double NAT (CGNAT) forwarding ports is not an option as we do not control forwarding on the second gateway. This will limit you to any of the solutions that include a device outside your network with a public port that tunnels traffic into your server.

      • ArborNode@lemmy.shutes.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        27 days ago

        To some degree yes. I ran an experiment to see and found there is just too much of the existing internet infrastructure not implementing IPV6 for this to be reliable. For instance, you can’t use it for email intake because only 2 major players do IPV6.

        You still get dynamic assignments from the ISP and have to automate keeping your AAAA records up to date.

        The short answer is, it depends. For what OP is doing here, I expect it would work.

        If anyone else has messed with this, I’d love to here about it. Might be good as it’s own post.

  • Reannlegge@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    28 days ago

    I have a Flint 2 with a vanilla install of openWRT, that hosts wireguard. I have 2 static IPs, because I thought hey running my own mail and smtp services cannot be that hard (turns out yes it is hard and not worth the time to deal). Any who I have Wireguard running on my firewall and Caddy running on one of my pi’s, it gets TLS from lets encrypt.

    I have a couple of domains that Caddy uses to point things out to the world or my LAN/vLANs/VPNs. Very few of the things go out to the whole world, but if I wanted to share say a Jellyfin server with someone I could wip up a VPN that only allows Jellyfin through and points DNS to my piholes. Why do I mention my ad blocker? I mention pihole because that what hosts the prefix to my domain names that Caddy can serve up, I do not remember why I set it up like this, I would have to look through my notes but pihole points “service”.domain1or2.xyz to caddy which than points to the right service.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    20 days ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    CA (SSL) Certificate Authority
    CSAM Child Sexual Abuse Material
    DNS Domain Name Service/System
    Git Popular version control system, primarily for code
    ISP Internet Service Provider
    SSD Solid State Drive mass storage
    TLS Transport Layer Security, supersedes SSL
    VPN Virtual Private Network
    VPS Virtual Private Server (opposed to shared hosting)
    nginx Popular HTTP server

    [Thread #74 for this comm, first seen 6th Aug 2026, 09:00] [FAQ] [Full list] [Contact] [Source code]